Play Ransomware Group Strikes Walser Automotive Group

Incident Date:

May 29, 2024

World map

Overview

Title

Play Ransomware Group Strikes Walser Automotive Group

Victim

WALSER AUTOMOTIVE GROUP, LLC

Attacker

Play

Location

Edina, USA

Minnesota, USA

First Reported

May 29, 2024

Play Ransomware Group Targets WALSER AUTOMOTIVE GROUP

Company Profile: WALSER AUTOMOTIVE GROUP

Walser Automotive Group, a retail and motor vehicle manufacturing company based in Edina, Minnesota, operates multiple luxury brands such as Acura, Audi, BMW, Jaguar, Land Rover, Lexus, Mercedes-Benz, MINI, and Porsche. The company is distinguished by its innovative one-price system and customer-centric approach, setting it apart in the industry. With over 60 years of history and a revenue of approximately $200 million, Walser Automotive Group is a medium-sized company with a strong presence in the Twin Cities.

Attack Overview

The Play ransomware group targeted Walser Automotive Group, resulting in a ransomware attack that was disclosed on the dark web on June 2, 2024. The breach, which was added to records on May 30, 2024, has garnered significant attention with 931 views. The attackers have published compromised files online, posing a serious threat to the company's data security.

Ransomware Group Profile: Play Ransomware Group

The Play ransomware group, operated by Ransom House, is a significant player in the cybercrime landscape, known for targeting Linux systems. This group has evolved from data theft to deploying cryptographic lockers, showcasing a sophisticated approach to ransomware tactics. Play ransomware shares similarities with Baseline Babuk in terms of encryption methods and victim communication, making it a formidable threat to organizations.

Company Vulnerabilities

Walser Automotive Group's size and reputation in the automotive industry make it an attractive target for threat actors like the Play ransomware group. The company's extensive network of luxury brands and customer data could have been a key motivation for the attackers. Additionally, the company's reliance on digital systems for sales, financing, and service operations may have provided avenues for the ransomware group to penetrate its systems.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.